Microsoft Defender for IoT
Incidents and response

Accelerate OT alert workflows - Microsoft Defender for IoT

In brief

The page now highlights required Azure portal permissions or OT sensor access, clarifies migration guidance for alert exclusion rules, and warns that deleting custom alert rules is irreversible. Links and wording were also updated.

What Defender admins need to know

Review the prerequisites and migration guidance. Disable rules instead of deleting them when they may be needed later.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

AccelerateManage and accelerate OT alert workflows in Microsoft Defender for IoT

  • Create custom alert rules to identify specific traffic in your network

Each method requires specific Azure portal permissions or OT sensor access. See the Prerequisites before you begin.

Prerequisites

Before you use the procedures on this page, note the following prerequisites:

To ... You must have ...
Create alert suppression rules on the Azure portal A Defender for IoT subscription with at least one cloud-connected OT sensor and access as a Security Admin, Contributor, or Owner.
Create a DNS allowlist on an OT sensor An OT network sensor installed and access to the sensor as the default Admin user.
  • For locally managed sensors, create alert exclusion rules on the OT sensor, either using the UI or the API.

Create alert suppression rules on the Azure portal (Public Preview)

Migrate suppression rules from an OT sensor

If you're currently using an OT sensor with cloud-connected sensors, we recommend that you migrate any alert exclusion rules from the OT sensor to the Azure portal as suppression rules before you start creating new suppression rules. Any suppression rules configured on the Azure portal override alert exclusion rules that exist for the same sensors on the OT sensor.

To export alert exclusion rules and import them to the Azure portal:

Create alert comments on an OT sensor

Use the following steps toTo create custom alert comments on your OT sensor that team members can add to individual alerts.alerts, complete this procedure.

  1. Sign into your OT sensor and select System Settings > Network Monitoring > Alert Comments.

Edits made to custom alert rules, such as changing a severity level or protocol, are tracked in the Event timeline page on the OT sensor.

For more information,information about viewing changes in the Event timeline, see Track sensor activity.

Disable, enable, or delete custom alert rules

Disable custom alert rules to prevent them from running without deleting them altogether.

In the Custom alert rules page, select one or more rules, and then select Disable, Enable, or Delete in the toolbar as needed.

Create alert exclusion rules via API

Use the Defender for IoT API

In the Custom alert rules page, select one or more rules, and then select Disable, Enable, or Delete in the toolbar as needed.

Create alert exclusion rules via API

Use the Defender for IoT API to create alert exclusion rules from an external ticketing system or other system that manage network maintenance processes.

Use the Create alert exclusions API reference API to define the sensors, analytics engines, start time, and end time to apply the rule.

For more information, see Defender for IoT API reference.

Next stepsstep

[!div class="nextstepaction"] Microsoft Defender for IoT alerts